ByteShield
1.29K subscribers
99 photos
32 videos
107 files
519 links
Download Telegram
Reversing Microsoft Defender's signatures for evasion.

Deep dive into VDM guts - a gzip-compressed files with no encryption to evade entire signatures with just 1 byte change.


https://retooling.io/blog/an-unexpected-journey-into-microsoft-defenders-signature-world
👍1
An unexpected journey into Microsoft Defender's signature World


https://retooling.io/blog/an-unexpected-journey-into-microsoft-defenders-signature-world
UPX Unpacking: Manual Reverse Engineering

Master the full process of analyzing packed PE files: setting hardware breakpoints on the stack, locating the tail jump and fixing the Import Address Table

https://guidedhacking.com/threads/how-to-unpack-upx-using-x64dbg.20985/